Send CORs headers for browser applications
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- c, javascript
- Lĩnh vực
- backend-api-design, networking, security
Hướng nghiên cứu
Bắt đầu bằng cách lần theo việc xử lý phản hồi HTTP của CUPS cho các endpoint IPP và xem xét các yêu cầu CORS được liên kết trong issue. Xác định cách các origin đáng tin cậy sẽ được cấu hình và xác thực; được coi là hoàn tất khi các ứng dụng trình duyệt có thể gửi các yêu cầu IPP với các header bắt buộc mà không để lộ rộng rãi các máy in.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
It would really simplify things for users of applications served through the browser that need to print documents if some sort of CORs configuration could be enabled via CUPs.
If you aren't familiar with CORs - this is solved simply by adding a few HTTP headers. Ideally, headers are only allowed for a set of trusted domains which can be enabled in some fashion by the user (i.e. the user needs to allow prints from "fancyprintjobs.example.com"). This page does a better job describing it than I could do here: https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
If it is helpful, I can go into more detail about the specific header key/values required to facilitate communication between the application running inside the browser and CUPs. However, know it is simply adding a couple of http headers to the response based on the domain requests are made from.
The browser respects a CORs policy when allowing http requests from an application (i.e. javascript code) to endpoints served from a different domain than the application. When CORs is enabled, javascript applications are able to print directly to CUPs. Without CORs, browsers disallow the ability to submit IPP jobs to CUPs from an application running in the browser context.
Currently, users have two options - they can manually print each document by downloading it via the browser and using a local program to print. This is slow and requires the user to set the print settings for each type of job. Since the remote application already knows how it should be printed (and can set these settings automatically via IPP, it is frustrating for - and confusing to many - users to configure the printer correctly for different types of documents.
The better option is to allow the application to print directly via IPP. However, CORs restrictions make this difficult since they are not considered by CUPs.
Since CUPs does not allow CORs configuration, the user must do one of the following at present:
- (easiest approach from a user perspective) place the printer on the public internet. This allows the server component of the browser application to submit print jobs. Hopefully the user exposes their printer securely - however - considering most people cannot configure a router, it is unlikely that the average person working from home is sharing their printer over the internet securely. This seems worse than exposing CORs to the LAN. There is a little more to this as most users have dynamic ip addresses, but that is ignored for the sake of discussion.
- place a reverse proxy in front of CUPs and apply CORs headers there. This method allows the Javascript application running in the browser to print via their local network without exposing the printer over the public internet.
Of the two choices - CORs is safer and simpler for the end user. However there is a large barrier to entry here due to the configuration of a reverse proxy - this really isn't feasible for the average user who just expects printing to work.
Since there are ways to side step the issue - people are doing it. However, since the steps are complicated, it isn't being done well and users are unknowingly creating risk.
Please consider adding CORs support to CUPs in any fashion. It would be very useful to the end users.
- Ngôn ngữ chính
- C
- Star
- 1.8k
- Fork
- 341
- Merge trung bình
- 15 giờ 28 phút
- Pull request đã merge (30 ngày)
- 5
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của OpenPrinting/cups
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
OpenPrinting/cups#1721 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
ippeveprinter: collection-valued job attributes are never exported to the command (IPP_MEDIA_COL always empty)Có thể đã có người làm @michaelrsweet đã nhận hôm nay. Đang mởbug documentation priority-low
OpenPrinting/cups#1725 · 2 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
I18n for CUPS webapp pagesĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 55/100
OpenPrinting/cups#1724 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Buffer overflow in cupsSideChannelSNMPGet()Có thể đã có người làm @michaelrsweet đã nhận 5 ngày trước. Đang mởinvestigating
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
OpenPrinting/cups#1719 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Integer overflow in httpGetDateTime()Có thể đã có người làm @michaelrsweet đã nhận 5 ngày trước. Đang mởbug priority-low
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 65/100
OpenPrinting/cups#1717 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của OpenPrinting/cups
Issue tương tự
-
Add c++23 mapping to nvccĐang mởfeature request
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 86/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
FujiNetWIFI/fujinet-firmware#1730 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
-
[openssl] update to 3.6.5Đang mởcategory:port-update
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 2 ngày